On this page
Most of the businesses we talk to about Microsoft Purview fall into one of two camps. Either they have never heard of it, or someone has told them it is an enterprise product they cannot afford.
Both groups are usually already paying for a good chunk of it.
Purview is the data governance and compliance side of Microsoft 365. Sensitivity labels, data loss prevention, retention schedules, legal holds, eDiscovery, audit logging. It is not a separate product you install. It is a set of controls sitting in your tenant right now, almost all of them switched off, waiting for somebody to make a decision.
This is a plain accounting of what is in the box, what genuinely costs extra, and the things nobody tends to mention until they matter.
The naming has changed more than the product
If you go looking for this and end up confused, that is not your fault.
Microsoft has renamed and reorganised this area repeatedly. There was Azure Purview for data cataloguing and a separate Microsoft 365 compliance centre. Those merged into one Microsoft Purview. The compliance portal at compliance.microsoft.com has been retired, and everything now lives at purview.microsoft.com.
The eDiscovery side moved too. On 31 August 2025, Microsoft retired all the classic experiences — classic Content Search, classic eDiscovery (Standard) and classic eDiscovery (Premium). Content Search was not removed; it was absorbed, and now runs inside an eDiscovery case. The old export tool was retired on the same day.
There is a small artefact of this worth knowing, because it caused genuine confusion. Microsoft publishes a plan comparison for its small and medium business licences. In the June 2025 edition, the Business plans had a row called “Content Search”. In the August 2026 edition, that row reads “eDiscovery (Standard), including Hold and Export”. Same entitlement. Different label. If you read the older document, or an article written from it, you would conclude Business Premium has less than it does.
One more thing you will trip over: Microsoft’s own documentation has not fully caught up. The eDiscovery getting-started page still says an E3 or E5 licence is required. That sentence is written for enterprise customers and is contradicted by the newer small-business comparison. Microsoft is not consistent with itself here, so be careful whose summary you trust — including ours. Check the plan comparison at aka.ms/M365BusinessPlans and look at the publish date printed inside the file.
What Business Premium actually includes
Verified against Microsoft’s security and compliance licensing guidance and the plan comparison published 1 August 2026 (see Sources below):
- eDiscovery (Standard), including hold and export. You can preserve mailboxes and sites, search across the tenant, and export what you find.
- Litigation Hold. Preserve everything in a mailbox indefinitely.
- Audit (Standard). A unified log of user and admin activity, retained 180 days for most workloads.
- Data loss prevention for Exchange Online, SharePoint and OneDrive.
- Manual sensitivity labelling, including encryption and access restrictions.
- Retention policies and labels, including Teams chat and channel messages.
- Exchange archiving with auto-expanding archive up to 1.5 TB.
- Compliance Manager, with assessment scope depending on your agreement.
That is a serious amount of capability for a licence most small businesses already hold. It is also, in our experience, almost entirely unconfigured.
What it doesn’t include
The line falls in sensible places. Business Premium gives you the manual, policy-driven versions. The automatic and investigative ones cost more:
- Automatic sensitivity labelling, in apps or in the service
- Endpoint DLP, and DLP for Teams chat
- Records management, and rules-based or machine-learning retention
- eDiscovery (Premium) and Audit (Premium)
- Insider Risk Management
- Information Barriers, Customer Key, Customer Lockbox, Privileged Access Management
Here is the part that gets misreported: you do not have to move to E3 or E5 to get them. Microsoft sells a Purview Suite built specifically for Business Premium, at CAD $13.60 per user per month billed annually, capped at 300 seats, as listed on Microsoft’s Purview pricing page in September 2026. There are also three narrower add-ons covering information protection and governance, insider risk, and eDiscovery with audit — all of which can now sit on a Business Premium base.
The enterprise version of the suite is the one that requires E3. The small-business SKU exists precisely so you do not need it.
Two limits worth knowing before you rely on it
Retention is not backup, and Microsoft agrees
This is the single most expensive misunderstanding in this area.
A retention policy stops content being permanently deleted. When someone deletes a retained file, it moves quietly into a preservation area — the Preservation Hold library in SharePoint, Recoverable Items in Exchange — where an administrator can go and find it. That is real protection against a deletion, deliberate or otherwise.
It is not a backup. Retention gives you no point-in-time restore and no way to roll a site back to yesterday after ransomware. A file overwritten with a bad version relies on version history or a backup, not on retention.
Microsoft sells backup separately. Microsoft 365 Backup is its own pay-as-you-go product, and its documentation states that retention and deletion policies from Purview do not affect the backup recovery window, which stays isolated from them. Read those two products as designed for different jobs.
Microsoft also warns against using legal holds as a retention strategy. Holds are meant to be short-term, user-specific and legal in purpose. Retention is long-term, content-based and compliance-driven. Using one for the other creates administrative mess and, eventually, an unpleasant surprise.
eDiscovery does not see everything
If you ever have to produce documents, you should know this before you certify anything.
Some content cannot be indexed and so cannot be searched by keyword. Unsupported file types. Password-protected attachments. Files encrypted by something other than Microsoft. And — the one that catches people — attachments encrypted by a Purview sensitivity label, because Exchange cannot index the contents. Microsoft’s own benchmark is that most organisations have under 1% of content by volume and under 12% by size in this category. Small, but not nothing, and not randomly distributed: it is disproportionately the sensitive material.
Those items also cannot be previewed. You have to export them to find out what they are. And the tool that reindexes them properly is a premium feature, so on Business Premium you work around the gap rather than closing it.
Microsoft’s specific warning is worth repeating: do not use query-based holds to preserve encrypted or partially indexed material, because the hold may not apply as intended. Use a location-based hold instead. When the stakes are legal, preserve the whole location and narrow afterwards.
Where your Purview data actually lives
This one deserves its own heading, because it is not obvious and it matters to exactly the organisations we work with.
If your tenant was signed up in Canada, Microsoft commits under its Product Terms (data residency overview) to keeping your Exchange, SharePoint, OneDrive and Teams data in Canada at rest, by default, at no extra cost. Canadian datacentre regions are described only to city level: Toronto and Quebec City.
Purview is not in that default commitment. In Microsoft’s own residency tables, Purview is covered only by the paid Advanced Data Residency add-on. Even then, the commitment extends to six services: data loss prevention, information barriers, information protection, Audit (Standard), Audit (Premium), and data lifecycle management.
eDiscovery is not on that list. Neither is Insider Risk Management, Communication Compliance or Compliance Manager. For those we could not find a published residency commitment in Microsoft’s residency documentation as of the verification date below. The honest statement is that Microsoft makes no residency commitment for them that we can point to — not that they are held anywhere in particular, which would be a guess.
Two further details, since this is usually asked in the same breath. Advanced Data Residency has to be bought for every paid seat in the tenant, calculated on purchased seats rather than assigned ones, or the commitment does not apply at all. And Microsoft notes separately that residency is about data at rest: processing may still occur outside Canada, as may support.
If you are a First Nation, a health organisation, a law firm or a public body, that is a board-level fact, and it is better to know it before you build a programme on top of it.
On PIPEDA and PHIPA, plainly
You will see MSPs advertise Microsoft 365 as PIPEDA compliant or PHIPA compliant. We are not going to, because Microsoft does not.
We could not find a Microsoft 365 PIPEDA compliance page. The Canadian privacy laws material sits in the compliance offerings documentation and is written around Azure. Its own wording is careful: there is no formal certification that cloud service providers can use to comply with Canadian privacy laws, and in-scope services can help you meet the requirements. That is a meaningfully weaker claim than “compliant”, and the difference is the whole point.
The same page corrects something we hear repeated backwards all the time: PIPEDA does not require Canadian businesses to keep personal information in Canada. Depending on your province or sector you may face residency requirements, but they do not come from PIPEDA itself.
PHIPA appears in two places worth naming. It is mentioned in that Azure-scoped privacy analysis, which is about Azure and not Microsoft 365 or Purview. And there is a Compliance Manager assessment template named for PHIPA — which is a structured self-assessment tool, not a certification, and it sits behind a premium licence.
None of this means Purview is not useful for a PHIPA or PIPEDA obligation. It is genuinely useful. It means the compliance is yours, the tooling is Microsoft’s, and anyone blurring the two is selling something.
Where to start
Not with a purchase.
Start by finding out what your licence already entitles you to, then turn on the things you are already paying for, in an order that matches your actual risk. For most of the organisations we work with that means data loss prevention on outbound email first, because that is where information leaves; then retention, because that is what an auditor or a funder asks about; then labels, once people understand why they are labelling.
Legal holds are the exception. Those you set up before you need them, because the day you need one is the day it is already too late to be reading about it.
If you want a straight answer about what is sitting unused in your tenant, get in touch. We would rather switch on what you own than sell you an upgrade — and if it turns out you do need the add-on, at least you will know precisely what for.
Sources and last verified
Last verified 11 September 2026. Licensing entitlements, prices and residency commitments change; check the linked pages before relying on a figure.
- Microsoft 365 security and compliance licensing guidance, Microsoft Learn: which Purview features each plan includes.
- Microsoft Purview pricing, Microsoft: the Business Premium suite and add-on prices.
- Microsoft 365 Backup overview, Microsoft Learn: backup as a separate product, isolated from retention.
- Learn about retention policies and labels, Microsoft Learn: retention versus holds.
- Partially indexed items in eDiscovery, Microsoft Learn: what search cannot see.
- Data residency for Microsoft 365 and Advanced Data Residency, Microsoft Learn: what the Canada commitment covers.
- Canadian privacy laws, Microsoft Learn: Microsoft’s own wording on PIPEDA and PHIPA.